« Volver al listado

CVE-2015-9105

Estado: ModificadaMedia (5.4)—

Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-9105",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@synology.com",
      "affectedData": [
        {
          "vendor": "Synology",
          "product": "Video Station",
          "versions": [
            {
              "status": "affected",
              "version": "1.2"
            },
            {
              "status": "affected",
              "version": "1.5"
            },
            {
              "status": "affected",
              "version": "1.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-30T13:29:00.287",
  "references": [
    {
      "url": "http://www.fortiguard.com/zeroday/FG-VD-15-107",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@synology.com"
    },
    {
      "url": "http://www.fortiguard.com/zeroday/FG-VD-15-108",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@synology.com"
    },
    {
      "url": "https://www.synology.com/en-global/support/security/Video_station_1_5_0772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@synology.com"
    },
    {
      "url": "http://www.fortiguard.com/zeroday/FG-VD-15-107",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.fortiguard.com/zeroday/FG-VD-15-108",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.synology.com/en-global/support/security/Video_station_1_5_0772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@synology.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos."
    },
    {
      "lang": "es",
      "value": "Varias vulnerabilidades de XSS (cross-site scripting) en Synology Video Station versión 1.2 y anteriores a la 1.2-0455, versión 1.5 y anteriores a la 1.5-0772 y versión 1.6 y anteriores a la 1.6-0847, permiten a atacantes remotos autenticados inyectar secuencias de comandos web o HTML a través del nombre de archivo (1) o (2) nombre de la colección de videos."
    }
  ],
  "lastModified": "2026-06-17T00:35:49.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.2-0439:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81F897FC-85D3-49F0-81BE-D7D5A61139CA"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.2-0443:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F5F29DC-3EC2-426D-95EF-738740132F12"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.2-0447:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39CCFB49-AFDE-45DC-80BD-0F2B1D2226F8"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.2-0451:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9BE07BC-C272-49ED-B40A-25C606162FBD"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.2-0453:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25A5FA37-18B2-4A4E-9722-92D495904CCE"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.5-0753:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2298653F-BC1D-438E-A8F4-AE92BF00B94E"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.5-0754:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D274409-AD82-4111-888B-A11E182607BA"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.5-0757:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "532C3C7A-5511-4044-8553-E0C3AE33D773"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.5-0763:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1A14F9F-71CA-4F47-8A8B-EA5FFD177FE9"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.5-0770:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6618F6CE-AA13-4153-8C38-C069C50339F0"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.6-0835:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75EDDEDA-572F-4BF5-9C0C-0689C8381B12"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.6-0840:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "513AC704-4458-4DFB-924D-5D87CD9F51C9"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.6-0841:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABEE8DFB-50A4-4FEC-8794-EAD9A9347D2B"
            },
            {
              "criteria": "cpe:2.3:a:synology:video_station:1.6-0844:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95AC4B5C-EC9E-4DB8-B0A9-B020293B263D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@synology.com"
}